In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-07-20T00:00:00
Updated: 2024-10-24T16:50:01.779Z
Reserved: 2023-04-07T00:00:00
Link: CVE-2023-30200
Vulnrichment
Updated: 2024-08-02T14:21:44.684Z
NVD
Status : Modified
Published: 2023-07-20T20:15:10.177
Modified: 2024-11-21T07:59:53.940
Link: CVE-2023-30200
Redhat
No data.